Monarch-X Ai Sign in

Trust

How Monarch-X Ai handles your data, and the controls you have over it.

Where your data is processed

Your account and everything it stores are held in the United Kingdom, in London data centres.

To answer a question, the question is processed by AI model services working under contract to us, in the same London region.

When live web sources are used (Check the news, and live sources on Pro and Enterprise), the question is sent to a web-search service with personal details such as names, email addresses, phone numbers and card numbers replaced by stand-ins first. That service may process the query outside the United Kingdom. A workspace owner can switch live web search off for the whole workspace in Settings (UK-only web sources).

Payments are handled by our payment provider, which may process payment details outside the United Kingdom.

What is kept

Account: your email address, a password hash (never the password), your plan and billing status, and the preferences you set in Settings.

Your work: chats (kept on our servers so they are the same on every device), saved answers, life folder dates and reminders, and anything you import. A chat you delete is hidden everywhere at once; its text is removed when your workspace's retention period passes or when the account is erased.

Proof of answers: every answer is stamped with a reference and written to an append-only ledger. The ledger holds fingerprints (SHA-256 hashes) of the question and the answer, never the text.

Money records: usage, invoices and payments are company records the law requires us to keep. Card details are handled entirely by our payment provider and never reach our servers.

Who processes data for us

We use a small number of processors under contract, described here by category:

  • cloud hosting and managed database (United Kingdom, London);
  • AI model services that produce answers;
  • a web-search service for live sources (personal details replaced before any query is sent);
  • a payment provider (card details never reach our servers);
  • email delivery for sign-in links, invitations and reminders.

The named list of sub-processors is part of our data processing agreement and is released to organisations that have signed it.

Training and improvement

Customer conversations are not exported for training or improvement. Questions from customer workspaces are recorded with a private scope that the improvement export never reads; the only rows it reads are from the operator's own accounts.

There is no opt-in for customers today. If one is ever offered, it will be off until your workspace turns it on, and these terms will say so first.

See and control your data

Download your audit trail (every answer's reference, time and fingerprints) from Settings, as CSV or JSON. The person who opened the account can download the whole account's trail.

Export any chat as a stamped PDF or a Word document from the chat screen.

Delete a saved answer, a life-folder date or a chat at any time.

Ask us to erase your account and all associated data through the contact form while signed in. We complete erasure within 7 days.

Risk register

The main risks to your data and to the service, what is in place today and what is planned.

RiskIn placePlanned
A single operator: the service depends on one person.Every deploy goes through the release gate; snapshots and a rollback script exist.
Unauthorised production access.Production access is limited to the owner. Operator sessions expire after 12 hours; sensitive operator actions need a sign-in within the last 15 minutes.Access policy published (this page).
A record is changed or removed without trace.Decision tables are guarded: every sanctioned change is written to a hash-chained ledger with who and why; answers are stamped into an append-only ledger that anyone can check at /audit.
Personal data sent outside the UK.Personal details are replaced by stand-ins before a web search; a workspace can turn live web search off (UK-only web sources).A UK-based web-search service (awaiting supplier agreement).
The assistant states a data-handling policy that was never written.Questions about data handling are answered only from owner-approved wording; until it exists the answer points to the privacy policy.
Spend beyond money received.Every paid call is reserved against the workspace's prepaid allowance before it runs.
Data kept longer than a customer needs.Per-workspace retention with a nightly, ledgered deletion job.
Loss of the database.Managed database with automated backups kept for 14 days, and a database snapshot taken at each verified release.Restore drills recorded and their latest result shown on /status.

Access policy

Production systems are operated by a single operator. Production access is limited to the owner.

Operator accounts are separate from customer accounts. An operator cannot use the service as a customer, operator sessions expire after 12 hours, and sensitive operator actions (such as changing an account or publishing an agreement) require a sign-in within the last 15 minutes.

Operators do not read customer conversations. Chats are private to the person: there is no team view and no owner or manager override.

Every change to accounts, plans and other decision records is recorded, with who made it and why, in a hash-chained ledger that cannot be edited.